ID

VAR-201104-0313


TITLE

SAP GUI 'saplogon.ini' File Buffer Overflow Vulnerability

Trust: 1.1

sources: IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1469 // BID: 47359

DESCRIPTION

The SAP GUI is a graphical user interface client for SAP software. An attacker can build a saplogon.ini file containing a specially crafted label that overwrites the files on the user's upgrade server, causing a buffer overflow when the user installs the upgrade. Successful exploitation of a vulnerability can execute arbitrary code in the context of an application. SAP GUI is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Failed attacks will cause denial-of-service conditions

Trust: 0.99

sources: CNVD: CNVD-2011-1469 // BID: 47359 // IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1469

AFFECTED PRODUCTS

vendor:sapmodel:guiscope:eqversion:7.1

Trust: 1.1

vendor:sapmodel:guiscope:eqversion:7.2

Trust: 0.9

vendor:sapmodel: - scope:eqversion:*

Trust: 0.4

vendor:sapmodel:gui sp3scope:neversion:7.20

Trust: 0.3

vendor:sapmodel:gui sp21scope:neversion:7.1

Trust: 0.3

vendor:sapmodel:guiscope:eqversion:7.2*

Trust: 0.2

sources: IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1469 // BID: 47359

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 47359

TYPE

Boundary Condition Error

Trust: 0.3

sources: BID: 47359

PATCH

title:SAP GUI 'saplogon.ini' file buffer overflow vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/3549

Trust: 0.6

sources: CNVD: CNVD-2011-1469

EXTERNAL IDS

db:BIDid:47359

Trust: 0.9

db:CNVDid:CNVD-2011-1469

Trust: 0.8

db:IVDid:87AE49E0-1F98-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 87ae49e0-1f98-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1469 // BID: 47359

REFERENCES

url:http://dsecrg.com/pages/vul/show.php?id=317http

Trust: 0.6

url:http://dsecrg.com/pages/vul/show.php?id=317

Trust: 0.3

url:http://www.sap.com/

Trust: 0.3

sources: CNVD: CNVD-2011-1469 // BID: 47359

CREDITS

Dmitriy Chastuhin

Trust: 0.3

sources: BID: 47359

SOURCES

db:IVDid:87ae49e0-1f98-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-1469
db:BIDid:47359

LAST UPDATE DATE

2022-05-17T02:01:22.331000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-1469date:2011-04-15T00:00:00
db:BIDid:47359date:2011-04-14T00:00:00

SOURCES RELEASE DATE

db:IVDid:87ae49e0-1f98-11e6-abef-000c29c66e3ddate:2011-04-15T00:00:00
db:CNVDid:CNVD-2011-1469date:2011-04-15T00:00:00
db:BIDid:47359date:2011-04-14T00:00:00